Welcome to TMCnet.com
TMC Launches New Web Sites: Cable WiMAX  |  Satellite  |  Robotics  |  IT |   IP VPN |   ITEXPO West begins in:   Register Now!
Columnists:
E-mail this page to a friend Order reprints online Print this page Bookmark this page Free magazines Free newsletters RSS-XML alerts
Security Attack of the Day
SIP and Open Standards Featured Article
February 22, 2008

Security Attack of the Day

Technology Columnist

There’s nothing that gets people "up in arms" than terrorism. In the spirit of keeping terrorists away, here is the "Security Attack of the Day" so you can plan to accordingly.

SIP-Specific Event Notification as described in RFC-3265 is the ability to request asynchronous notification of events. "This proves useful in many types of SIP services for which cooperation between end-nodes is required. Examples of such services include automatic callback services (based on terminal state events), buddy lists (based on user presence events), message waiting indications (based on mailbox state change events), and PINT (PSTN-Internet Internetworking) (based on call state events). The general concept is that entities in the network can subscribe to resource or call state for various resources or calls in the network, and those entities (or entities acting on their behalf) can send notifications when those states change." The following is an example of a type of attack based SIP-Specific Event Notification. The animated tutorial can found at http://blog.tmcnet.com/cross-talk/


A Hacker sends a "Messages-Waiting: yes" messages to all phones in a SIP-network. Phone process this NOTIFY status message and initiates icon/blinking Message Waiting display. Users initiate access to voicemail system leading to system overload. Since no new voice messages are found users initiate support calls wasting time on unfounded problem.

The complete details and recommendations for SIP and other types of VoIP security can be found in the SIP Essentials and OCS-Office Communications Server classes. For more go to http://www.techtionary.com

-----
Tom Cross (News - Alert) is a technology columnist and a regular blogger for TMCnet. To read more of his articles, please visit his
blog.

 


E-mail this page to a friend Order reprints online Print this page Bookmark this page Free magazines Free newsletters RSS-XML alerts

Subscribe FREE to all of TMC's monthly magazines. Click here now.
TMC LOGO
Technology Marketing Corporation,
One Technology Plaza, Norwalk, CT 06854 USA
Ph: 800-243-6002, 203-852-6800; Fx: 203-866-3326
General comments: tmc@tmcnet.com. Comments about this site: webmaster@tmcnet.com.
About   Contact  Advertise
Technology Marketing Corp. 1997-2008 Copyright. Privacy Policy Sitemap
Advanced